- Research Article
13
- 10.1016/j.cose.2004.06.010
A hybrid scheme for multicast authentication over lossy networks
- Aug 21, 2004
- Computers & Security
- Heba K Aslan
A hybrid scheme for multicast authentication over lossy networks
Coordinated checkpointing is an effective fault tolerant technique in distributed system as it avoids the domino effect and require minimum storage requirement. Most of the earlier coordinated checkpoint algorithms block their computation during checkpointing and forces minimum-process or non-blocking but forces all nodes to takes checkpoint even though many of them may not be necessary or non-blocking minimum-process but takes useless checkpoints or reduced useless checkpoint but has higher synchronization message overhead or has high checkpoint request propagation time. Hence in mobile distributed systems there is a great need of minimizing the number of communication message and checkpointing overhead as it raise new issues such as mobility, low bandwidth of wireless channels, frequently disconnections, limited battery power and lack of reliable stable storage on mobile nodes. In this paper, we propose a minimum-process coordinated checkpointing algorithm for mobile distributed system where no useless checkpoints are taken, no blocking of processes takes place and enforces a minimum-number of processes to take checkpoints. Our algorithm imposes low memory and computation overheads on MH's and low communication overheads on wireless channels. It avoids awakening of an MH if it is not required to take its checkpoint and has reduced latency time as each process involved in a global checkpoint can forward its own decision directly to the checkpoint initiator.
A hybrid scheme for multicast authentication over lossy networks
A hybrid scheme for multicast authentication over lossy networks
Intermedia Synchronization Protocol for Continuous Media Using MPEG-4 in Mobile Distributed Systems
The preservation of temporal dependencies among a group of processes that exchange continuous media at runtime is a key issue for emerging mobile distributed systems (MDS), such as monitoring of biosignals and interactive multiuser games. Although several works are oriented to satisfy temporal dependencies, most of them are not suitable for MDSs. In general, an MDS is characterized by the absence of global references (e.g. shared memory and wall clock), host mobility, limited processing and storage capabilities in mobile hosts, and limited bandwidth on wireless communication channels. This paper proposes an asymmetric synchronization protocol to be used at runtime in an MDS without using a common reference. One main aspect of our synchronization protocol is that it translates temporal constraints to causal dependencies of the continuous media data as seen by the mobile hosts. We simulate the protocol by considering a cellular network environment and by using MPEG-4 encoders. The simulation results show that our protocol is effective in reducing the synchronization error. In addition, the protocol is efficient in terms of processing and storage costs at the mobile devices, as well as in the overhead attached per message across the wired and wireless channels.
Read moreCAxCNN: Towards the Use of Canonic Sign Digit Based Approximation for Hardware-Friendly Convolutional Neural Networks
The design of hardware-friendly architectures with low computational overhead is desirable for low latency realization of CNN on resource-constrained embedded platforms. In this work, we propose CAxCNN, a Canonic Sign Digit (CSD) based approximation methodology for representing the filter weights of pre-trained CNNs.The proposed CSD representation allows the use of multipliers with reduced computational complexity. The technique can be applied on top of state-of-the-art CNN quantization schemes in a complementary manner. Our experimental results on a variety of CNNs, trained on MNIST, CIFAR-10 and ImageNet datasets, demonstrate that our methodology provides CNN designs with multiple levels of classification accuracy, without requiring any retraining, and while having a low area and computational overhead. Furthermore, when applied in conjunction with a state-of-art quantization scheme, CAxCNN allows the use of multipliers, which offer 77% logic area reduction, as compared to their accurate counterpart, while incurring a drop in Top-1 accuracy of just 5.63% for a VGG-16 network trained on ImageNet.
Read moreA GLOBAL STOCHASTIC PERSPECTIVE ON IOT DEVICE AUTHENTICATION USING DIGITAL CERTIFICATE MECHANISM FOR INTERNET OF THINGS (IOT) DEVICES
Abstract. The increased deployment of Internet of Things (IoT) has revolutionized global connectivity through applications such as smart cities, smart industries, healthcare systems, and industrial automation. However, resource-constrained IoT devices face severe security challenges, particularly in device authentication. Traditional authentication mechanisms based on symmetric and asymmetric cryptography introduce excessive communication and computation overhead, making them unsuitable for constrained IoT environments. In this paper, we propose a secure and lightweight device authentication mechanism based on digital certificates from a global stochastic perspective. The proposed framework considers the dynamic and uncertain behavior of IoT networks while ensuring secure identification and communication. The protocol employs asymmetric cryptography, hash functions, nonces, and timestamps to prevent impersonation, replay, and device capture attacks. The security properties of the proposed protocol are formally verified using the AVISPA tool under the Dolev-Yao attacker model. Performance evaluation demonstrates low communication, storage, and computational overhead, making the proposed mechanism suitable for Industrial IoT, smart cities, defense systems, and other mission-critical IoT applications.
Read moreCEFEEL: C ommunication- E fficient FE derated L earning for Personal Assistant Applications
Smartphones have rapidly become ubiquitous with more than five billion users worldwide. Equipped with advanced sensors such as GPS, cameras, and microphones, they generate large amounts of diverse data. Much of this data, including locations, call logs, images, and online activities, is private. A suitable model training architecture is required to enhance usability through intelligent applications while preserving data privacy and security. In this paper, we develop a communication-efficient federated learning (CEFEEL) framework for smartphone personal assistant applications to protect data privacy and maintain user experience with low communication and computational overhead. The proposed framework identifies parameters that have converged early in the training phase and hence can be frozen or communicated intermittently, reducing communication overhead without compromising model accuracy. Extensive experiments demonstrate the robustness of our approach against unbalanced and non-IID data distributions. The experiments show that our developed framework, named FedFreeze and FedFreeze+ techniques, outperforms state-of-the-art FL algorithms like FedAvg in reducing communication and computational costs, preserving privacy, and maintaining training efficiency with comparable accuracy.
Read moreApproximate aggregation techniques for sensor databases
In the emerging area of sensor-based systems, a significant challenge is to develop scalable, fault-tolerant methods to extract useful information from the data the sensors collect. An approach to this data management problem is the use of sensor database systems, exemplified by TinyDB and Cougar, which allow users to perform aggregation queries such as MIN, COUNT and AVG on a sensor network. Due to power and range constraints, centralized approaches are generally impractical, so most systems use in-network aggregation to reduce network traffic. However, these aggregation strategies become bandwidth-intensive when combined with the fault-tolerant, multipath routing methods often used in these environments. For example, duplicate-sensitive aggregates such as SUM cannot be computed exactly using substantially less bandwidth than explicit enumeration. To avoid this expense, we investigate the use of approximate in-network aggregation using small sketches. Our contributions are as follows: 1) we generalize well known duplicate-insensitive sketches for approximating COUNT to handle SUM, 2) we present and analyze methods for using sketches to produce accurate results with low communication and computation overhead, and 3) we present an extensive experimental validation of our methods.
Read moreTrInc-Based Secure and Privacy-Preserving Protocols for Vehicular Ad Hoc Networks
In vehicular ad hoc networks (VANETs), vehicles communicate with each other and with roadside units (RSUs) in order to enhance road safety, improve traffic management and provide infotainment services. Along with the growth of VANETs, some challenges are emerging. Although there are many research work on VANETs, cheating attacks are still not well resolved such as selective message relaying attack, faked information reporting attack and resource-consuming attack launched by selfish or malicious participants. To deal with this kind of attacks, we present two novel lightweight security mechanisms by equipped each vehicle's On-Board Unit (OBU) with a small elegant module called TrInc, which is a trusted hardware and composed of only a non-decreasing counter and a key. We observe that TrInc-based method not only can effectively resist against cheating attacks in safety- oriented, convenience-oriented, and commercial-oriented VANET applications, but also significantly defend various aspects of security and privacy in VANETs. Compared with previous works, our proposal features low communication and computation overhead, less memory requirements, and good network scalability.
Read moreSTRENGTHENING DIGITAL LOCAL SELF-GOVERNMENT THROUGH SECURE IOT INFRASTRUCTURE: A LIGHTWEIGHT COAP-BASED AUTHENTICATION FRAMEWORK FOR MUNICIPAL SERVICES
Local government and sub-national authorities increasingly rely on Internet of Things (IoT) infrastructures to support smart municipal services such as traffic management, waste collection, public lighting and environmental monitoring. The reliability and security of these digital infrastructure are critical for effective local self-government, public service continuity and citizen trust. However, most municipal IoT deployments operate under strict resource constraints, making conventional security mechanisms impractical. This paper proposes a lightweight and secure mutual authentication framework designed for resource-constrained IoT devices used in local government and municipal service environments. By leveraging symmetric cryptographic primitives and the Constrained Application Protocol (CoAP), the proposed approach enables secure device authentication without relying on computationally expensive DTLS handshakes. A state-based authentication mechanism is introduced to enhance resistance against replay, impersonation and denial of service attacks. Security analysis and experimental evaluation demonstrate that the proposed framework achieves strong protection against common attack vectors while maintaining low communication, storage and computational overhead. From a local self-government perspective, the proposed approach provides a practical security foundation for scalable and cost-effective deployment of IoT-based municipal services, supporting digital transformation at the sub-national level.
Read moreA Privacy Preserving Truthful Spectrum Auction Scheme Using Homomorphic Encryption
Dynamic spectrum reallocation, under which the spectrum owners temporarily share the underutilized spectrum to secondary users for economic profit, is an important approach to improve the spectrum utilization ratio. Auction is believed to be a natural marketing tool to incentivize the spectrum owners, and thus redistribute the idle spectrum efficiently. Extensive researches have been done in the problem of truthful spectrum auction, in which the bidders bid based on their true valuations of the spectrum. The true valuation of the individual bidder, however, is a private information which should be protected against exposure. In this paper, we propose a privacy preserving truthful spectrum auction scheme by utilizing homomorphic encryption. The proposed scheme reveals the group bids but hides the users' bids even from the auctioneer. The evaluation results show that the proposed scheme achieves good spectrum utilization efficiency with low communication and computation overheads.
Read moreBlock-CLAP: Blockchain-Assisted Certificateless Key Agreement Protocol for Internet of Vehicles in Smart Transportation
In the Internet of Vehicles (IoV), numerous potential applications have come up with the use of the Internet of Things (IoT)-empowered smart devices. In IoV, vehicles, roads, street signs and traffic lights can accordingly adjust to changing conditions in order to assist drivers, and also to improve safety, ease congestion and pollution reduction. Since various entities in an IoV environment make communications over public channels, there are potential security threats. To deal with such serious threats, we design a new blockchain-assisted certificateless key agreement protocol for IoV in smart transportation context, called Block-CLAP. In Block-CLAP, through authentication key management, traffic-centric data reach to a cluster head (CH) and then to its nearby road-side unit (RSU) securely using the established secret keys. A cloud server (CS) then securely collects the information from its attached RSUs and create the transactions. Later, the transactions are formed into blocks by the CS in a Peer-to-Peer (P2P) cloud servers network, and the blocks are verified and added through voting-based consensus algorithm in the blockchain. The detailed security analysis through formal, informal and formal security verification, and comparative study show that Block-CLAP provides superior security and has low communication and computational overheads as compared with other existing competing authentication schemes in the IoV environment. Finally, the blockchain-based implementation of Block-CLAP has been performed to measure computational time needed for a varied number of transactions per block and also for a varied number of blocks mined in the blockchain.
Read moreOrthogonal, Fault-Tolerant, and High-Precision Clock Synchronization for the Controller Area Network
The controller area network (CAN) is facing a great opportunity. The maturity of this technology makes many researchers believe that CAN may be adopted in more critical systems. However, the suitability of CAN for these challenging applications strongly depends on our capacity to integrate all the solutions already available into a single, comprehensive architecture. We claim that clock synchronization plays a fundamental role in such architecture. Therefore, the means to achieve a solution fulfilling the expected requirements on reliability, cost, and precision must be deeply investigated. This paper discusses the relevance of clock synchronization in the future of CAN systems and describes a novel solution to supply this service. This solution exhibits several advantages: it provides very high precision, causes very low communication and computation overhead, and includes mechanisms to provide fault tolerance. Moreover, and in contrast to previous proposals, it is designed to be orthogonal to the rest of the system. Thus, it can be directly incorporated to any CAN system, without having to replace any of the components, which reduces the cost increment caused by the new service.
Read moreAggregatable Subvector Commitments for Stateless Cryptocurrencies
An aggregatable subvector commitment (aSVC) scheme is a vector commitment (VC) scheme that can aggregate multiple proofs into a single, small subvector proof. In this paper, we formalize aSVCs and give a construction from constant-sized polynomial commitments. Our construction is unique in that it has linear-sized public parameters, it can compute all constant-sized proofs in quasilinear time, it updates proofs in constant time and it can aggregate multiple proofs into a constant-sized subvector proof. Furthermore, our concrete proof sizes are small due to our use of pairing-friendly groups. We use our aSVC to obtain a payments-only stateless cryptocurrency with very low communication and computation overheads. Specifically, our constant-sized, aggregatable proofs reduce each block’s proof overhead to a single group element, which is optimal. Furthermore, our subvector proofs speed up block verification and our smaller public parameters further reduce block size.
Read moreEfficient Privacy-Preserving Electricity Theft Detection With Dynamic Billing and Load Monitoring for AMI Networks
In advanced metering infrastructure (AMI), smart meters (SMs) are installed at the consumer side to send fine-grained power consumption readings periodically to the system operator (SO) for load monitoring, energy management, and billing. However, fraudulent consumers launch electricity theft cyber attacks by reporting false readings to reduce their bills illegally. These attacks do not only cause financial losses but may also degrade the grid performance because the readings are used for grid management. To identify these attackers, the existing schemes employ machine-learning models using the consumers' fine-grained readings, which violates the consumers' privacy by revealing their lifestyle. In this article, we propose an efficient scheme that enables the SO to detect electricity theft, compute bills, and monitor load while preserving the consumers' privacy. The idea is that SMs encrypt their readings using functional encryption (FE), and the SO uses the ciphertexts to: 1) compute the bills following the dynamic pricing approach; 2) monitor the grid load; and 3) evaluate a machine-learning model to detect fraudulent consumers, without being able to learn the individual readings to preserve consumers' privacy. We adapted an FE scheme so that the encrypted readings are aggregated for billing and load monitoring and only the aggregated value is revealed to the SO. Also, we exploited the inner-product operations on encrypted readings to evaluate a machine-learning model to detect fraudulent consumers. The real data set is used to evaluate our scheme, and our evaluations indicate that our scheme is secure and can detect fraudulent consumers accurately with low communication and computation overhead.
Read moreEnd-to-end secure delivery of scalable video streams
We investigate the problem of securing the delivery of scalable video streams so that receivers can ensure the authenticity (originality and integrity) of the video. Our focus is on recent scalable video coding techniques, e.g., H.264/SVC, that can provide three scalability types at the same time: temporal, spatial, and quality (or PSNR). This three-dimensional scalability offers a great flexibility that enables customizing video streams for a wide range of heterogeneous receivers and network conditions. This flexibility, however, is not supported by current stream authentication schemes in the literature. We propose an efficient authentication scheme that accounts for the full scalability of video streams: it enables verification of all possible substreams that can be extracted and decoded from the original stream. Our evaluation study shows that the proposed authentication scheme is robust against packet losses, adds low communication and computation overheads, and is suitable for live streaming systems as it has short delay.
Read morePrivacy-Preserving Blockchain-Based Energy Trading Schemes for Electric Vehicles
An energy trading system is essential for the successful integration of Electric Vehicles (EVs) into the smart grid. In this paper, leveraging blockchain technology, we first propose a privacy-preserving charging-station-to-vehicle (CS2V) energy trading scheme. The CS2V scheme is useful in crowded cities where there is a need for a charging infrastructure that can charge many EVs daily. We also propose a privacy-preserving vehicle-to-vehicle (V2V) energy trading scheme. The V2V scheme is useful when charging stations are not available or far and cheaper prices can be offered from EVs, e.g., if they charge from renewable energy sources. In the V2V scheme, the privacy of both charging and discharging EVs including location, time, and amount of power are preserved. To preserve privacy in both schemes, EVs are anonymous, however, a malicious EV may abuse the anonymity to launch Sybil attacks by pretending as multiple non-exiting EVs to launch powerful attacks such as Denial of Service (DoS) by submitting multiple reservations/offers without committing to them, to prevent other EVs from charging and make the trading system unreliable. To thwart the Sybil attacks, we use a common prefix linkable anonymous authentication scheme, so that if an EV submits multiple reservations/offers at the same timeslot, the blockchain can identify such submissions. To further protect the privacy of EV drivers, we introduce an anonymous and efficient blockchain-based payment system that cannot link individual drivers to specific charging locations. Our experimental results indicate that our schemes are secure and privacy-preserving with low communication and computation overheads.
Read more